Data processing facts
Effective 26 July 2026
Location and subprocessors
| Application, database and semantic index | Hetzner HEL1, Helsinki, Finland |
|---|---|
| Recordings and uploaded files | Hetzner Object Storage HEL1, Helsinki, Finland |
| AI inference outside Google Calendar | Fireworks AI, Mistral AI, OpenAI or xAI, selected by the service |
| Employee Knowledge embeddings | OpenAI API Platform, usage-based billing |
| Optional integrations | Zoom, Telegram and Google only when enabled by the company |
| Internet search | Disabled for employee knowledge answers |
Hetzner identifies HEL1 as its Helsinki, Finland location. See the provider location record. AI providers do not receive a tenant's full database: they receive only the material required for the requested transcription, summary, extraction or answer. Provider retention and training controls differ; the current pilot does not promise zero data retention at every inference provider.
Google Calendar isolation
Google Calendar is used only by the scheduling and employee-coordination subsystem. Raw, aggregated, anonymized, and derived Google Calendar data is never sent to any provider or model listed below, is never included in AI prompts, and is never used to create, train, or improve AI/ML models. Free/busy blocks are processed transiently inside the AI Sales Brain deployment at Hetzner to calculate available slots. The provider inventory below describes separate AI Sales Brain capabilities and does not mean that those providers receive Google API User Data.
| AI provider | Plan or tier | Current data terms |
|---|---|---|
| Fireworks AI | Serverless Standard API, pay-as-you-go | Open-model prompts and generations have zero retention unless the customer opts in. |
| Mistral AI | Scale API plan, pay-as-you-go | API privacy controls govern training and retention; Labs models are not used. |
| OpenAI | API Platform, usage-based billing | API inputs and outputs are not used for training by default; standard abuse-monitoring retention may be up to 30 days. |
| xAI | xAI API team, usage-based billing | API inputs and outputs are not used for training without permission; default retention is 30 days unless ZDR is enabled. |
Security controls and limits
- Traffic is encrypted with TLS; integration secrets use AES-256-GCM.
- Database backups are encrypted with age before upload.
- Object storage is private and versioned. Non-current versions expire after 14 days.
- Hetzner Object Storage does not provide encryption at rest by default. Do not upload special-category or highly sensitive personal data in the current pilot.
- We do not publish a customer RTO, RPO or response-time SLA for this pilot.
The storage limitation is documented by Hetzner in its Object Storage FAQ.
Retention and deletion
A company administrator can request account deletion in Settings. Access is disabled immediately. Tenant records and object versions are purged within 30 days; encrypted database backups and non-current object versions are retained for no more than 14 days. The service keeps a minimal deletion ledger without company content as proof of execution.
Russia restriction
The service is not offered to customers established in Russia and is not intended for processing personal data of Russian citizens. Customers must not submit such data or any data where doing so would breach Russian data-localisation, export or sanctions rules, and are responsible for the lawfulness and classification of data they provide. This allocation does not exclude obligations that applicable law places directly on us.